CVE-2026-50148
Last modified
CVE-2026-50148 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metabase | Metabase | >= 1.54.0, < 1.54.24 |
| Metabase | Metabase | >= 1.55.0, < 1.55.24 |
| Metabase | Metabase | >= 1.56.0, < 1.56.25 |
| Metabase | Metabase | >= 1.57.0, < 1.57.19 |
| Metabase | Metabase | >= 1.58.0, < 1.58.14 |
| Metabase | Metabase | >= 1.59.0, < 1.59.10 |
| Metabase | Metabase | >= 1.60.0, < 1.60.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-50148?
How severe is CVE-2026-50148?
How do I fix CVE-2026-50148?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50141Woodpecker is a CI/CD engine. Starting in version 3.0.0 and …7.1
- CVE-2026-50142libheif is a HEIF and AVIF file format decoder and encoder. …7.5
- CVE-2026-50143The Apify MCP server enables AI agents to extract data from …8.1
- CVE-2026-50144ncnn is a high-performance neural network inference framewor…7.1
- CVE-2026-50146Astro is a web framework. Prior to 6.3.3, when a component u…6.1
- CVE-2026-50147Metabase is an open-source business intelligence and embedde…7.6
- CVE-2026-50149Contour is a Kubernetes ingress controller using Envoy proxy…6.5
- CVE-2026-5015A vulnerability was determined in elecV2 elecV2P up to 3.8.3…4.3
- CVE-2026-50151oras-go is a Go library for managing OCI artifacts. Prior to…7.5
- CVE-2026-50152Ceph is an open-source distributed storage platform providin…9.1
- CVE-2026-50157Auth0 Symfony is a Symfony SDK for Auth0 Authentication and …6.5
- CVE-2026-50158yutu is an AI-powered toolkit for managing and growing YouTu…7.7
Are you affected by CVE-2026-50148?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
